Back

HIGH

Kernel: gsm multiplexing race condition leads to privilege escalation

Published Dec 21, 2023

Description

A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system.

Affected products

Remediation

Vendor solution

This flaw can be mitigated by preventing the affected `n_gsm` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.

Red Hat statement

This vulnerability is critical because it can be exploited to escalate privileges, directly threatening system security. Despite requiring local access and having a high attack complexity, the potential to severely impact confidentiality, integrity, and availability justifies its "Important" rating.

Red Hat mitigation

This flaw can be mitigated by preventing the affected `n_gsm` kernel module from being loaded. For instructions on how to blacklist a kernel module, please see https://access.redhat.com/solutions/41278.

References (34)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Dec 21, 2023
Updated Aug 6, 2026
Reserved Dec 6, 2023

CISA Vulnrichment

No data

NVD

Status Modified
Modified Aug 6, 2026

Red Hat

Severity Important
Public date Dec 21, 2023
Bugzilla 2255498

ENISA EUVD

Assigner redhat
Published Dec 21, 2023
Updated Aug 6, 2026

GitHub

No data